Oracle Solaris vulnerabilities
549 known vulnerabilities affecting oracle/solaris.
Total CVEs
549
CISA KEV
6
actively exploited
Public exploits
29
Exploited in wild
8
Severity breakdown
CRITICAL45HIGH116MEDIUM285LOW103
Vulnerabilities
Page 6 of 28
CVE-2019-2545MEDIUMCVSS 4.0v10v112019-01-16
CVE-2019-2545 [MEDIUM] CVE-2019-2545: Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: LD
Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: LDoms IO). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability c
nvd
CVE-2019-2543MEDIUMCVSS 5.3v10v112019-01-16
CVE-2019-2543 [MEDIUM] CVE-2019-2543: Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: Ke
Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via KSSL to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized read acces
nvd
CVE-2019-2544MEDIUMCVSS 4.0v10v112019-01-16
CVE-2019-2544 [MEDIUM] CVE-2019-2544: Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: Ke
Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can
nvd
CVE-2018-20685MEDIUMCVSS 5.3Exploitedv102019-01-10
CVE-2018-20685 [MEDIUM] CWE-863 CVE-2018-20685: In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrict
In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side.
nvd
CVE-2018-3275HIGHCVSS 7.4v11.32018-10-17
CVE-2018-3275 [HIGH] CVE-2018-3275: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: LibKMIP).
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: LibKMIP). The supported version that is affected is 11.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized creation, del
nvd
CVE-2018-3273HIGHCVSS 8.1v11.32018-10-17
CVE-2018-3273 [HIGH] CVE-2018-3273: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Remote Ad
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Remote Administration Daemon (RAD)). The supported version that is affected is 11.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Solaris. Successful attacks require human interaction from a pers
nvd
CVE-2018-3265MEDIUMCVSS 4.9v11.32018-10-17
CVE-2018-3265 [MEDIUM] CVE-2018-3265: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Zones). T
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Zones). The supported version that is affected is 11.3. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized
nvd
CVE-2018-3268MEDIUMCVSS 5.3v11.32018-10-17
CVE-2018-3268 [MEDIUM] CVE-2018-3268: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: SMB Serve
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: SMB Server). The supported version that is affected is 11.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via SMB to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a partia
nvd
CVE-2018-3263MEDIUMCVSS 5.6v11.32018-10-17
CVE-2018-3263 [MEDIUM] CVE-2018-3263: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Sudo). Th
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Sudo). The supported version that is affected is 11.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized update, insert
nvd
CVE-2018-3271MEDIUMCVSS 5.3v11.32018-10-17
CVE-2018-3271 [MEDIUM] CVE-2018-3271: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel Zo
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel Zones). The supported version that is affected is 11.3. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. While the vulnerability is in Solaris, attacks may significan
nvd
CVE-2018-3274MEDIUMCVSS 5.7v11.32018-10-17
CVE-2018-3274 [MEDIUM] CVE-2018-3274: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel).
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11.3. Easily exploitable vulnerability allows low privileged attacker with network access via SMB to compromise Solaris. Successful attacks require human interaction from a person other than the attacker. Successful atta
nvd
CVE-2018-3269MEDIUMCVSS 4.3v11.32018-10-17
CVE-2018-3269 [MEDIUM] CVE-2018-3269: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: SMB Serve
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: SMB Server). The supported version that is affected is 11.3. Easily exploitable vulnerability allows low privileged attacker with network access via SMB to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial
nvd
CVE-2018-3264MEDIUMCVSS 4.4v11.32018-10-17
CVE-2018-3264 [MEDIUM] CVE-2018-3264: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel).
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized upd
nvd
CVE-2018-3267MEDIUMCVSS 5.3v11.32018-10-17
CVE-2018-3267 [MEDIUM] CVE-2018-3267: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: LFTP). Th
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: LFTP). The supported version that is affected is 11.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via FTP to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Sola
nvd
CVE-2018-3172MEDIUMCVSS 5.3v11.32018-10-17
CVE-2018-3172 [MEDIUM] CVE-2018-3172: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: RPC). Sup
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: RPC). Supported versions that are affected are 10 and 11.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via Portmap v3 to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a
nvd
CVE-2018-3272MEDIUMCVSS 6.2v11.32018-10-17
CVE-2018-3272 [MEDIUM] CVE-2018-3272: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel Zo
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel Zones Virtualized NIC Driver). The supported version that is affected is 11.3. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability
nvd
CVE-2018-2922LOWCVSS 2.5v11.32018-10-17
CVE-2018-2922 [LOW] CVE-2018-2922: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel).
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11.3. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized read
nvd
CVE-2018-3266LOWCVSS 3.9v11.32018-10-17
CVE-2018-3266 [LOW] CVE-2018-3266: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Verified
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Verified Boot). The supported version that is affected is 11.3. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in unauthori
nvd
CVE-2018-3270LOWCVSS 1.8v11.32018-10-17
CVE-2018-3270 [LOW] CVE-2018-3270: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel).
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11.3. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks require human interaction from a person other than t
nvd
CVE-2018-2928HIGHCVSS 8.1v11.32018-07-18
CVE-2018-2928 [HIGH] CVE-2018-2928: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: RAD). The
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: RAD). The supported version that is affected is 11.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Solaris. Successful attacks require human interaction from a person other than the attacker. Suc
nvd